[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ipsec
Subject:    Inconsistencies between values and field size
From:       Greg Carter <carterg () entrust ! com>
Date:       1997-01-17 16:26:00
[Download RAW message or body]


I don't know if has been pointed out yet, please ignore if it has...

ISAKMP Draft 6
Proposal Payloads
Protocol ID - 1 octet

DOI Draft 2 (Dec 9)
The following table lists the values for the Security Protocol
   Identifiers referenced in an ISAKMP Proposal Payload for the IPSEC
   DOI.
...

   The values 4-15360 are reserved to IANA.  Values 15361-16384 are
   reserved for private use.

The size of the field in the ISAKMP draft the DOI values don't match up.

Easy to fix

Proposal Payload
# of transforms - 2 octets

but look at Transform Payload

# Transforms - 1 octet

So the max you can send in a proposal is 1 octet worth, therefore change
the Protocol ID field to 2 octets and # of Transforms to 1 octet in the
Proposal Payload.
Bye.
----
Greg Carter
Entrust Technologies
carterg@entrust.com
>

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic